Skip to main content
Proposed by the European Commission, COM(2025) 838

The European
Business Wallet

A digital identity wallet for organisations, not for people.

It would give every company, institution and public body in the EU one legally recognised way to prove who it is, who may act on its behalf and which credentials it holds: across borders, in seconds, without sending another scanned PDF.

Aligned with European standards and initiatives
eIDAS 2.0
European Digital Identity
OpenID Foundation
Why it exists

Business is done between organisations. The EUDI Wallet was built for individuals.

Every cross-border tender, credit check and permit application still rests on documents a counterparty cannot verify without picking up the phone. The Business Wallet would close that gap at the level of the legal person.

Legal certainty

Identification, seals and mandates, powers of attorney at their core, that would carry the same legal weight in every Member State, under one regulation, with an auditable trail for compliance.

Three capabilities, not one

The organisation would be issuer, holder and verifier, not just a holder as under the EUDI Wallet: it could issue credentials, hold what it is issued, and verify what counterparties present.

Interoperable by design

One set of specifications. A credential issued in Tallinn is verifiable in Lisbon, with no bilateral integration.

Many people, separate roles

Not one person's wallet: employees and representatives would act under their own mandates, each scoped to what their role allows.

Control over company data

The organisation would decide what it discloses, to whom and for how long: never more than the transaction requires.

Less administrative weight

Tender files, tax statements, contracts and other business documents presented as machine-verifiable credentials instead of scanned attachments.

Always on for the business

A business runs 24/7: the wallet would need to support machine-to-machine calls and integration with back-office systems, not only interactive use by a person.

Ready for what follows

Built for the acceptance obligations arriving across regulated sectors, and for use cases that do not exist yet.

Use cases

Built for every business interaction

From compliance and procurement to supply chains and permits: wherever an organisation has to prove something about itself.

Compliance and legal filings

Registration extracts, tax standing, licences and annual statements shared as credentials with a verifiable issuer.

Public procurement

Submit an ESPD once and reuse it. Contracting authorities verify eligibility without requesting the same evidence twice.

KYC and due diligence

Onboard a counterparty in minutes: legal status, ownership, mandates and signatories checked at source.

Supply chain and product data

Certificates of origin, conformity and sustainability travelling with the goods instead of in an inbox.

Access, permits and licences

Request, hold and present permits and access rights digitally: on site, at the gate, or in a portal.

E-invoicing and e-delivery

Sealed invoices and legally reliable delivery of documents, with evidence of who sent what, and when.

How it works

From issued credentials to trusted interactions

Five moves would take an organisation from a paper trail to a verifiable one. Scroll to follow them.

1

Issuers issue

Chambers of commerce, tax authorities, regulators and certification bodies issue verifiable credentials about the organisation: signed at source, checkable forever.

2

The organisation holds

They land in the Business Wallet: registration data, legal status, authorisations, certificates. The organisation is the holder, not an employee, not a platform.

3

People are authorised

Mandates issued from the Business Wallet land in each representative's personal EUDI Wallet, proving who may act, and within which limits.

4

Only what is asked for

When a counterparty asks a question, the wallet answers exactly that question. Selective disclosure keeps everything else private.

5

The relying party verifies

Signatures, issuer status and validity are checked against EU trust lists: instantly, without calling anyone, and without a bilateral integration.

Issuerstrusted at sourceChamber of commerceTax authorityRegulators & auditorsBusiness Walletthe organisationRegistration dataAuthorisationsCertificatesEUDI WalletrepresentativesPerson identityMandate to actLimits & validityRelying partybank, buyer, authorityVerifies signaturesChecks trust listsGrants access134verified

Under the Commission's proposal the Business Wallet would be issued to legal persons, while the EUDI Wallet stays with natural persons. The two are designed to work together.

Wallets

A growing ecosystem of business wallets

Providers across Europe are building wallets for organisations. These are listed in the FIDES ecosystem explorer.

View all wallets
SPAIN

Gataca Studio

Gataca Studio is a cloud-based digital identity platform enabling organizations to interact with ID wallets.

Learn more about Gataca Studio
ITALY

Namirial Wallet Enterprise

Business wallet platform that enables organizations to seamlessly manage, store, and present verifiable credentials in trusted digital ecosystems.

Learn more about Namirial Wallet Enterprise
NETHERLANDS

Sphereon VDX platform

Sphereon VDX is a verifiable data layer for policy-driven trust and audit-ready decisions.

Learn more about Sphereon VDX platform
EUROPEAN UNION

EUDIW Reference Issuer

Reference/demo web issuing service for the EUDI Wallet ecosystem (EUDIW Issuer).

Learn more about EUDIW Reference Issuer
FAQ

Questions worth asking

Short answers here. Every term links through to a fuller definition in the glossary.

Open the glossary
A digital identity wallet for a legal person, a company, association or public body, rather than for an individual. It would store credentials the organisation has been issued (registration, legal status, authorisations, certificates), present them selectively to counterparties, and seal and sign on the organisation’s behalf. The European Commission proposed it on 19 November 2025 as a dedicated instrument alongside the EUDI Wallet.
eIDAS 2 is Regulation (EU) 2024/1183, in force since 20 May 2024, which amended the original eIDAS Regulation and established the European Digital Identity Framework. It sets the trust framework the Business Wallet builds on: qualified trust services, trusted lists, and the specifications that make wallets interoperable across the Union.
No business is obliged to hold a wallet. The obligations fall on others: Member States must make at least one EUDI Wallet available to citizens and residents, and relying parties in regulated sectors, banking, telecoms, energy, transport, health, must accept it. The Business Wallet proposal is still moving through the ordinary legislative procedure, and the Parliament and the Council can still change it. No date is settled until the final text is adopted.
The EUDI Wallet is the personal wallet: it carries a natural person's identity data and attributes. The Business Wallet would carry the organisation's. The Commission's proposal deliberately separates the two, amending eIDAS so mandatory issuance of the EUDI Wallet relates to natural persons only. In practice they would interlock: a representative's EUDI Wallet holds the mandate that proves they may act for the organisation whose credentials sit in the Business Wallet.
A Qualified Electronic Registered Delivery Service is a trust service under eIDAS that transmits data between parties and produces evidence of sending, receipt and integrity, with a qualified timestamp. It is the registered post of the digital single market, and the mechanism by which a document sent to or from a wallet becomes legally reliable, not merely transmitted.
Start with an inventory: which documents does your organisation ask others for, and which does it have to produce itself? Those are your first credentials. Then identify the processes where you act as a relying party, follow the Architecture and Reference Framework, and pilot with a wallet provider or in one of the large-scale pilots. Organisations that map their authorisations and mandates now will be the ones ready to switch them on.